Didomi · Vulnerability Disclosure
Didomi Vulnerability Disclosure
Vulnerability disclosure
Didomi runs a coordinated vulnerability disclosure program on Hackerone.
AdvertisingAdTechCCPACMPConsentConsent ManagementDSARData PrivacyGDPRIAB TCFMarTechPreference ManagementPrivacyPrivacy RequestsRegulatory Compliance
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-13'
method: searched
source: https://www.didomi.io/security
info:
name: Didomi vulnerability disclosure
provider: didomi
description: >-
Didomi publishes a named security contact and an explicit invitation to
security researchers, in prose, on its security page. It does NOT run a
public bug bounty and does NOT serve a machine-readable security.txt.
checked: '2026-08-13'
program:
exists: true
type: security-contact
bug_bounty: false
platform: null
contact: security@didomi.io
policy_url: https://www.didomi.io/security
policy_text: >-
"If you are a security researcher who has potentially discovered a security
weakness or vulnerability in Didomi's systems, please send an email to
security@didomi.io"
safe_harbor: not stated
scope: not published
response_sla: not published
rewards: none published
pgp_key: null
evidence:
- url: https://www.didomi.io/security
http_status: 200
finding: >-
Security contact security@didomi.io published, alongside an ISO/IEC
27001:2022 certification claim and a description of Didomi's ISMS practices
(annual policy review, internal and access audits, vendor security
management, DDoS mitigation, encryption, intrusion detection, penetration
testing, vulnerability scanning, geographically separated datacenters,
background checks, mandatory security training).
fetched: '2026-08-13'
- url: https://didomi.io/.well-known/security.txt
http_status: 404
finding: No RFC 9116 security.txt served on the apex.
- url: https://api.didomi.io/.well-known/security.txt
http_status: 404
finding: No RFC 9116 security.txt served on the API host.
- url: https://www.didomi.io/security.txt
http_status: 404
finding: No security.txt at the legacy root path either.
- url: https://github.com/didomi/security
http_status: 200
finding: >-
A public repo named "security" exists ("Security information for the Didomi
platform") but its README is two lines and carries no policy — last pushed
2021-10-21.
- url: https://trust.didomi.io
http_status: 200
finding: >-
A Vanta-hosted trust center is served, but it renders client-side and
exposed no disclosure policy to an anonymous fetch.
searched_and_absent:
- platform: HackerOne
result: no Didomi program found
- platform: Bugcrowd
result: no Didomi program found
- platform: Intigriti
result: no Didomi program found
remediation:
- >-
Publish /.well-known/security.txt on didomi.io AND api.didomi.io per RFC
9116, with Contact: mailto:security@didomi.io, a Policy: URL, Expires:, and
Preferred-Languages:. The contact already exists — only the machine-readable
file is missing, which makes this the cheapest security-posture improvement
available to Didomi.
- Publish scope and safe-harbour terms alongside the contact.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/didomi-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.